Who we are
Pockit is a capture-and-recall app: the fastest way to save a digital thing from your phone, and the most reliable way to find it again. Pockit is built and operated by MindNdata. MindNdata is the operating entity behind Pockit and is the party responsible for how your personal data is handled (in the language of India's Digital Personal Data Protection Act, 2023, MindNdata is the "Data Fiduciary"). MindNdata AInnovations LLP is the operator of Pockit and is an incorporated limited liability partnership.
This policy is a standalone document: you can understand it on its own, without reading anything else. It is written in clear, plain language. It explains what data Pockit collects, why, who processes it on our behalf, how long we keep it, how it is protected, and the rights you have over it.
Pockit is India-first and is offered to users in India. This policy is designed to satisfy both India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 (together, "DPDP"), and Google Play's User Data policy, and Apple's App Store Review Guidelines.
Age, and who can use Pockit
Pockit does not collect or verify your age. There is no date-of-birth field at sign-up and no age check anywhere in the app, so Pockit cannot and does not determine how old you are.
Pockit is made for adults, and adults may use it normally. If you are under 18 and you use Pockit, you do so on the basis that a parent or legal guardian knows you are using it, approves of that use, and gives you the supervision and guidance appropriate to your age. You and your guardian take responsibility for your use on that footing. Where a user is a child, that parental knowledge, approval, and supervision is the basis on which their personal data is processed.
Whatever a user's age, Pockit does no behavioural monitoring of children and shows them no targeted advertising (consistent with Section 9 of the DPDP Act). If you are a parent or legal guardian and you want a child's account and data removed, you can delete it from within the app or on the web (see Section 10), or write to us at support@pockit.in and we will act on it.
The data we collect, and why
Pockit tries to collect only what it needs to do its one job well: save your things and let you find them again by meaning. The list below is itemised by data type, with the purpose of each. Pockit's Google Play Data safety declaration is derived from the same source — the app's actual code — and this list is kept consistent with it.
- Account information
- Your name, email address, and a user ID. You sign in with your Google account (Google Sign-In), with Sign in with Apple on iPhone, or with a code we email you. With Sign in with Apple, Apple gives us your name the first time only, and either your email address or, if you choose Hide My Email, a private relay address that forwards to you; we use it exactly like any other address.
- Sign in with Apple token
- A token Apple issues when you first sign in with Apple, stored encrypted on our server, only so that, when you delete your account, Pockit can tell Apple to end your Apple ID's sign-in to Pockit, as Apple requires. It is never used for anything else and is deleted with your account.
- Content you save ("your saves")
- Links, social posts and reels you share in, screenshots, images, documents and PDFs, and notes you write or dictate — plus the AI-generated titles, summaries, descriptions, and the numeric "embeddings" (vector representations of meaning) that Pockit derives from them
- App-activity and in-app search
- How you use the app, features you interact with, and the search queries you type inside Pockit
- Crash and diagnostic data
- Crash reports, error logs, and basic technical diagnostics
- App and device integrity verdict
- Google Play Integrity's verdict for your install: whether the app is the genuine Play build, whether the device passes Google's integrity checks, the licensing result, and the app version, stored against your account
- Device or app-instance identifiers
- An anonymous device or app-instance identifier generated by our analytics and crash-reporting tools
- Advertising identifier
- Your device's Android or iOS advertising ID (a resettable identifier your device operating system provides, not tied to your Pockit account)
What we do not collect. Pockit does not collect your location. Advertising is switched off (Section 4); on iPhone the Pockit app contains no advertising software at all. If advertising is switched on in a future Android version, ads would be shown through Google AdMob, which uses your device's advertising ID and may use device and usage information to serve and measure ads; where the law requires it, you are asked for consent first through Google's consent message, and you can reset or delete the advertising ID in your device settings. Pockit itself does not build advertising profiles and never gives advertisers the content of your saves. Pockit does not use any special/sensitive permissions for capture — saving works only through the Android system share sheet and the in-app Add flow. Pockit does not accept or store video files; a saved social post is represented by its link, thumbnail, and text only. See Section 4 for the full advertising disclosure, including how personalised and non-personalised ads work and exactly how to opt out.
Purpose limitation and data minimisation. We use your data only for the purposes listed above (and for the disclosed legal reasons in Section 9). We do not repurpose it for anything you have not been told about. If we ever want to use your data for a genuinely new purpose, we will tell you and, where the law requires it, ask for your consent.
Advertising
Advertising is switched off in this version of Pockit. No ads are shown, and nothing is sent to any advertising network. On Android the Google AdMob SDK is not started at all in this release, so no advertising identifier and no ad-serving signals leave your device. The iPhone app does not contain the AdMob SDK, or any other advertising or tracking software, at all, and Pockit does not track you across other companies' apps or websites.
Pockit is free and uncapped, and advertising is how we intend to fund it. The rest of this section is the complete, standalone disclosure of how advertising will work if and when we switch it on — what it would do with your data and how you would control it. We are publishing it now, ahead of time, so that nothing about it is a surprise later. If we do switch advertising on, it will be in a future version of the app and this section will be updated to say so (see Section 13).
Our advertising provider, if advertising is switched on. Pockit would show ads served by Google AdMob, and only AdMob — Pockit does not use a second advertising network. Ads would appear on seven surfaces inside the app: your Home feed, the grid view, Reels, Notes, Search results, Category pages, and the screen that confirms a save. On the six list-type surfaces an ad appears once in every three items you scroll past, styled and spaced exactly like the saves around it; on the save-confirmation screen, one ad appears every time, in a fixed space. Every ad carries a small "Ad" label so it is never mistaken for something you saved.
How a native ad is built. AdMob does not hand Pockit a finished, pre-made advertisement to display as-is. It hands back the parts of an ad — a headline, body text, an icon, a picture or short muted video, a call-to-action button, and the advertiser's name — and Pockit's own code lays those parts out inside Pockit's own visual design (its fonts, colours, corner radii and spacing), matching the surface the ad sits on. Google's required "AdChoices" control, which lets you see why an ad was shown and adjust ad settings, is placed by Google's SDK inside every ad; Pockit does not remove or obscure it. Ad video, where AdMob supplies one, starts muted, is never set to autoplay with sound, and never expands or interrupts what you were doing.
What we would share with Google, and what we would never share. To request, serve, and measure an ad, the AdMob SDK would send Google your device's advertising ID together with ordinary device and app-usage signals a mobile ad SDK needs (things like device model, operating system version, app version, general network type, and coarse ad-performance events). Pockit separately records, in its own analytics, the bare fact that an ad slot was shown or tapped (an "ad impression" or "ad click" event, with no more detail than that) so we can understand how the feature performs — this is the same processor (PostHog) and channel described in Section 7, and it never leaves our own systems. Google never receives the content of your saves, your account name or email, your search queries, or anything else Pockit stores for you. Ads are requested and rendered independently of, and without reference to, what you have saved or searched.
Personalised and non-personalised ads, and how you opt out. By default, AdMob may use your advertising ID and device signals to serve you personalised ads — ones chosen using Google's own advertising-interest signals for that device — unless you tell it not to. Where the law requires it, Pockit shows Google's consent message (built on Google's User Messaging Platform) before any ad request goes out, and your choice there is honoured for every ad you see afterward. Wherever you are, you always have two direct ways to switch to non-personalised ads or turn off ad personalisation entirely, without needing anything from Pockit:
On your device: Android — Settings → Privacy (or Google → Ads) → turn off "Ads personalisation" and, if you want to, reset or delete your advertising ID from the same screen. iOS — Settings → Privacy & Security → Apple Advertising / Tracking, and the per-app tracking control if Pockit ever requests it.
In your Google Account: visit adssettings.google.com while signed in to control ad personalisation across Google's advertising products, including the ads AdMob serves inside apps like Pockit.
Turning personalisation off does not stop ads from appearing — Pockit still shows the same number of ads, in the same places, styled the same way — it only stops Google from choosing them based on your advertising-interest signals.
Ad interactions are Google's, not Pockit's. Tapping an ad, and anything that happens after — the page or app it opens, any offer, purchase, or download involved — is handled entirely by Google and the advertiser. Pockit has no visibility into where a click leads and takes no part in it; see Section 9 of the Terms of Service for what this means for responsibility. If you have a concern about a specific ad's content, Google's AdChoices control on the ad itself is the fastest way to report or flag it.
Children. Consistent with Section 2, Pockit does not build behavioural advertising profiles of anyone and does not target ads to children. Because Pockit collects no age data, it cannot technically distinguish a child's device from an adult's; the commitment in Section 2 is the operative one, and a parent or guardian who has concerns can reach us at support@pockit.in.
Google's own disclosure. As required of every app that uses Google's advertising products, Google separately explains, in its own words, how it uses information from apps that use its services, at https://policies.google.com/technologies/partner-sites. That page, and Google's Ads Settings referenced above, sit alongside — not instead of — this section.
How saving and processing actually work
Understanding the data flow helps explain what happens to your content:
You share, we confirm instantly. When you share something to Pockit (or add it in-app), Pockit stores it and confirms the save. The confirmation is instant; understanding happens afterward.
Server-side background processing. After the save is confirmed, Pockit's servers read the item, write a title and description, decide which category it belongs in, and build the searchable representation. This runs in the background, on our servers.
Dictation uses your phone's speech recognition. When you dictate a note, Pockit asks your device's speech recognition service to turn your voice into text. Depending on your phone, that service (for example, Google's speech services) may process the audio itself. Pockit receives only the recognised text; it does not receive, upload or store the audio.
Formatting a note. When you dictate a note, or press the button that formats a note, the text of that note is sent through our server to Google's Gemini model, which returns it tidied into headings and lists. It is not stored by the model and comes straight back into your note.
Images are sent to our AI model as inline data (base64), not as public links. Because we already hold your file, our servers pass the image bytes directly to the AI model. Your images are not exposed as public URLs to make this work.
Your data is isolated to you. Every saved item, category, and vector is scoped to your account and protected by per-user row-level security in our database, so one user can only ever reach their own things.
Encryption in transit. Data moving between the app, our servers, and our processors is encrypted in transit using TLS/HTTPS. (Pockit does not provide end-to-end encryption, and this policy does not claim it.)
Legal basis and consent (DPDP)
We process your personal data on the basis of your consent, which you give when you create your account and use Pockit for the purposes described in this policy, and — where applicable — for the legitimate/legal uses the law permits (such as keeping records we are legally required to keep). You can withdraw your consent at any time, and doing so is as easy as giving it: you can delete your account and data from within the app or from the web page in Section 10. Withdrawing consent stops future processing for the affected purposes; it does not make lawful past processing unlawful.
Advertising signals (Section 4) are handled on a separate, narrower basis appropriate to them: the advertising identifier is your device's own resettable identifier, governed by Google's consent message and your device and Google Account controls described in Section 4, in addition to — not instead of — your general consent to use Pockit under this policy.
Who processes your data for us (our processors)
To run Pockit, we use a small set of specialist service providers. Each acts on MindNdata's behalf and under our instructions — they are processors (Data Processors), not independent controllers of your data. Because they are processors acting for us, in Google Play's terms your data is collected, but not "shared" (we do not hand your data to a third party for that third party's own purposes).
- Groq
- Groq runs the model that reads the text of your saves: the title, description, or note text you save goes to Groq so Pockit can describe it, categorise it, and expand a search query into a better search. Groq processes that text to return the answer and does not use it to train models.
- Google — Gemini (paid API tier)
- Google's Gemini model does the jobs Groq does not: "seeing" images, screenshots, and thumbnails (vision), generating the embeddings that make search work by meaning, and formatting the text of a note you dictate or ask Pockit to format into headings and lists. We use the paid Gemini API tier; on that paid tier, per Google's Gemini API terms, Google does not use your prompts or the model's responses to improve Google's products/models. (Separately, Google also provides Google Sign-In, which you use to log in.)
- Supabase
- Our core backend: authentication, the database (with per-user row-level security), file storage for your saved files, and the server-side functions that run processing and search.
- Resend
- Sends and receives transactional and support email (for example, account and support messages between you and us).
- PostHog
- Product analytics — how the app is used — received through a server-side proxy we run, so the app never holds analytics keys.
- Sentry
- Crash and error reporting, received through a server-side tunnel we run, so the app never holds a Sentry key.
- Apple — Sign in with Apple
- When you choose Sign in with Apple, Apple confirms who you are and gives Pockit your name (the first time only) and your email or Hide My Email relay address. Apple also tells our server when you stop using your Apple ID with Pockit, turn Hide My Email forwarding off or on, or delete your Apple Account, and Pockit acts on it (signing you out, or deleting the Pockit account of a deleted Apple Account; an account that also signs in with Google or email keeps those and loses only its Apple sign-in).
- Google — AdMob
- Not active in this version, and not in the iPhone app at all. If advertising is switched on in Android (Section 4), AdMob would serve the native ads and would receive the advertising ID and device/usage signals it needs to serve and measure an ad; it would never receive what you saved. Its SDK is not started in this release.
We choose processors that are appropriate to their single job, and we do not add processors that are unnecessary to running Pockit. If we add, remove, or change a processor, we will update this policy (see Section 13).
Processors used by the earlier version of Pockit (1.0). If you are still using Pockit 1.0 and have not updated, two additional processors apply to you, and they are listed here so this policy remains accurate for every user of Pockit, not only the newest version:
- Apify
- Fetched public details of a link you saved (for example the title, description, and preview image of a public post) so Pockit 1.0 could describe it.
- Scrape Creators
- Fetched public details of a saved social post for the same purpose, where Apify did not cover the source.
Neither is used by Pockit 2.0. In 2.0 the equivalent work is done on your own device, by Pockit itself reading the public page of the link you saved, and no third-party fetching service is involved. Updating to 2.0 removes both processors from the path your data takes.
International transfer of data
Pockit is operated from India, but some of the processors above operate and process data outside India. This means your personal data may be transferred to, stored on, or processed on servers located outside India. Where we do this, we rely on processors that commit to protecting your data and to processing it only on our instructions, and we transfer only what is needed for the purposes in this policy. By using Pockit you understand that your data may be processed outside India as described here.
How long we keep your data (retention) and deletion
We keep your account information and your saves for as long as your account is active, because that content is the service — it is the collection you came to Pockit to keep and search.
When you delete your account (see Section 10), we delete the personal data associated with it. We may retain limited data only where we have a disclosed, legitimate reason to — for example, to comply with a legal obligation, to resolve a dispute, or to enforce our terms — and only for as long as that reason genuinely requires. When the purpose is served or you withdraw consent, we erase the data, subject to those limited legal retention needs (consistent with DPDP erasure obligations).
An advertising ID is not something Pockit stores against your account in the first place (Section 4) — it lives on your device and is controlled by your device and Google Account settings, so deleting your Pockit account does not, by itself, reset it; use the device or Google Account controls in Section 4 if you also want to reset or opt out of it.
Deleting your account and data
You are always in control of removing your data. You can request deletion of your account and its associated data in two ways, and without reinstalling the app:
In the app: open Account, then Privacy, and choose Delete my account.
On the web, without the app: email support@pockit.in from the address on your account and ask us to delete it. We confirm the request is yours, delete the account and its data, and write back to tell you it is done. Both routes are set out in full at https://pockit.in/delete-account.
Deletion removes the personal data associated with your account (your account details, your saves, their derived titles/descriptions/embeddings, your categories, and the app and device integrity verdicts stored for fraud prevention and security), except for any limited data we must retain for the disclosed legitimate or legal reasons in Section 9. Deleting your account is also how you withdraw consent to processing.
If you signed in with Apple, deleting your account also tells Apple to end your Apple ID's sign-in to Pockit (Apple's token revocation), so Pockit no longer appears under Sign in with Apple in your Apple Account. If Apple cannot be asked (for example, you delete from an Android phone), your Pockit account is still deleted, and you can remove Pockit yourself in your iPhone's Settings, under your name, then Sign in with Apple.
Your rights (DPDP Sections 11–14)
As a person whose data we process (a "Data Principal"), you have the following rights, which you can exercise by contacting support@pockit.in or by using the in-app options:
Right to access (Section 11). You can ask for a summary of the personal data we process about you, a summary of our processing activities, and the identities of the processors with whom your data has been processed.
Right to correction and erasure (Section 12). You can ask us to correct, complete, update, or erase your personal data. Erasure is honoured except where we must retain data for the specified purpose or to comply with the law (see Section 9).
Right to grievance redressal (Section 13). You can raise a grievance with us using the mechanism in Section 12 below. This grievance route is a readily available means and must be exhausted before approaching the Data Protection Board of India.
Right to nominate (Section 14). You can nominate another individual to exercise your rights on your behalf in the event of your death or incapacity. Contact us at support@pockit.in to record a nomination.
Right to withdraw consent. You can withdraw your consent at any time, as easily as you gave it (see Sections 6 and 10).
We will not charge you for exercising these rights in the ordinary course, and we will respond within the timelines the law requires.
Grievance redressal and contact person
If you have a question, concern, or complaint about how Pockit handles your personal data — including anything about advertising in Section 4 — contact us first:
Contact for privacy and grievances: the Pockit Privacy Contact at MindNdata
Email: support@pockit.in
The Pockit Privacy Contact is the person designated to answer your questions about how we process your personal data (this fulfils the "contact person" requirement under Rule 9 of the DPDP Rules, 2025). Pockit is not a Significant Data Fiduciary, so a full Data Protection Officer is not required; the contact above is the point of contact for all data-processing questions and grievances.
Grievance timeline. We will acknowledge and work to resolve your grievance within 90 days of receiving it (consistent with Rule 14(3) of the DPDP Rules, 2025). If you are not satisfied after using this grievance mechanism, you may escalate to the Data Protection Board of India — but the law requires you to exhaust our grievance process first.
Changes to this policy
Pockit will evolve, and this policy will be updated over time. When we make a material change, we will update the effective date at the top, post the new version at https://pockit.in/privacy, and give you reasonable notice by appropriate means (such as in-app notice or email) before the change takes effect where the law requires it. Your continued use of Pockit after a change takes effect means you accept the updated policy. We encourage you to review this page periodically.
Our reservation on the future of Pockit
Today, Pockit is free and uncapped. Pockit shows Google AdMob native ads, as fully described in Section 4, and this section does not change the free-and-uncapped position today. That said, MindNdata expressly reserves the right, in the future and with reasonable notice, to:
- change how advertising works on Pockit — for example, the surfaces, formats, or frequency it appears with, or the ad network it uses — and to introduce a subscription or SaaS-style pricing model, or any other additional monetisation approach, alongside or instead of advertising;
- scale, change, or restructure the underlying operating entity behind Pockit (for example, converting MindNdata AInnovations LLP into a company), and to assign or transfer these Terms, this policy, the service, and associated data to that successor or acquiring entity as part of such a change; and
- update this policy and our Terms of Service over time to reflect the above, always with reasonable notice as described in Section 13.
If any such change affects how your personal data is used in a way that requires your consent, we will seek it as the law requires. Section 4 discloses advertising as it operates today; if we materially change how advertising works, we will update this policy and give notice as described above, and we will continue to honour the child-protection commitments in Section 2 (no behavioural monitoring of children, and no targeted advertising to children).
Contact
Questions about this policy or your data:
Email: support@pockit.in · Web: https://pockit.in/privacy